Privacy
This page is short because the tool collects nothing — that is the point. During the beta, downloads are direct and require no account, so there is no personal data to process.
The only personal data we would ever process is what you give us if you later choose to create an optional account (not currently offered).
This website
- No tracking cookies, no analytics, no advertising — the site is static HTML and CSS with no third-party scripts.
- Like any web server, the hosting provider may keep standard server logs (IP address, requested page); those logs belong to the host, not to us — see the hosting provider named in the legal notice.
Account (optional — not offered during the beta)
- We process your email and password (hashed with PBKDF2-SHA256, never stored in clear), or your name and email from Google if you use "Sign in with Google".
- Purpose: create and manage your account, authenticate you, and send verification and password-reset emails. Legal basis: performance of the contract (providing the account) and our legitimate interest in security.
- A strictly-necessary session cookie keeps you signed in — it is not used for tracking.
- Processors: Cloudflare (authentication service + accounts database), Resend (account emails, EU servers), Google (only with Google sign-in), Vercel (hosting). Cloudflare, Google and Vercel are US companies — transfers outside the EU are covered by Standard Contractual Clauses and/or the Data Privacy Framework. We never sell or rent your data.
- Retention: until you delete your account; sessions expire automatically. You have the rights of access, rectification, erasure, portability, objection and restriction.
The tool
- VRAMPilot runs locally on your machine. Your models, prompts, generations and the configurations it remembers stay on your machine, in a local SQLite file you can inspect (
vrampilot configs list) and bypass (--no-cache). - It transmits nothing to ZMLabs: no telemetry, no usage statistics, no crash reports.
- One network access exists, and only on first run: fetching the pinned llama.cpp server binary from its host (GitHub Releases by default, or any mirror you set via
GOVERNOR_SERVER_BASE_URL— including your own offline mirror). That request goes to the binary's host, not to ZMLabs, and the download is verified against a pinned SHA256 hash.
Contact
For any privacy question: contact.ZMLabs@proton.me — data controller: ZMLabs (Zahia Melouane), 24 rue de la Tartane, 34200 Sète, France. You may also lodge a complaint with the CNIL (cnil.fr).